<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: XDR add more values to incident classification in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-add-more-values-to-incident-classification/m-p/1248509#M9146</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="0" data-end="104"&gt;Another question, if you happen to know: is it possible to export all incidents to an external platform?&lt;/P&gt;
&lt;P data-start="106" data-end="243"&gt;For example, can I export incident data to a SQL database, including fields such as &lt;STRONG data-start="190" data-end="204"&gt;IncidentID&lt;/STRONG&gt;, &lt;STRONG data-start="206" data-end="221"&gt;Description&lt;/STRONG&gt;, and &lt;STRONG data-start="227" data-end="242"&gt;CloseReason&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P data-start="245" data-end="450" data-is-last-node="" data-is-only-node=""&gt;I need to perform a more granular classification of incidents — not just a true/false categorization — but also include additional flags aligned with &lt;SPAN class="hover:entity-accent entity-underline inline cursor-pointer align-baseline"&gt;&lt;SPAN class="whitespace-normal"&gt;European Union Agency for Cybersecurity&lt;/SPAN&gt;&lt;/SPAN&gt; (ENISA) taxonomy.&lt;BR /&gt;&lt;BR /&gt;I'll use only &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Feb 2026 18:10:12 GMT</pubDate>
    <dc:creator>tlmarques</dc:creator>
    <dc:date>2026-02-18T18:10:12Z</dc:date>
    <item>
      <title>XDR add more values to incident classification</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-add-more-values-to-incident-classification/m-p/1248395#M9136</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="77" data-end="89"&gt;Hi everyone,&lt;/P&gt;
&lt;P data-start="91" data-end="364"&gt;When I close each incident, I need to add the CSIRT taxonomy flags (from the ENISA Reference Incident Classification Taxonomy: &lt;A class="decorated-link" href="https://www.enisa.europa.eu/publications/reference-incident-classification-taxonomy" target="_new" rel="noopener" data-start="218" data-end="301"&gt;https://www.enisa.europa.eu/publications/reference-incident-classification-taxonomy&lt;/A&gt;) to the &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;case. &lt;BR /&gt;&lt;BR /&gt;Does anyone know if that is possible?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2026 14:19:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-add-more-values-to-incident-classification/m-p/1248395#M9136</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-02-17T14:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: XDR add more values to incident classification</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-add-more-values-to-incident-classification/m-p/1248400#M9137</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings for the day.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="0" data-end="209"&gt;Based on the provided internal documentation and technical cases, the ability to add custom taxonomy flags (such as a CSIRT taxonomy) depends on whether you are using Cortex XDR (Standard/Pro) or Cortex XSIAM.&lt;/P&gt;
&lt;HR data-start="211" data-end="214" /&gt;
&lt;H4 data-start="216" data-end="247"&gt;1. Cortex XDR (Standard/Pro):&lt;/H4&gt;
&lt;P data-start="249" data-end="421"&gt;In the standard version of Cortex XDR, there is currently no native support for creating user-defined custom fields or custom incident statuses specifically for taxonomies.&lt;/P&gt;
&lt;P data-start="249" data-end="421"&gt;&amp;nbsp;&lt;/P&gt;
&lt;H4 data-start="423" data-end="446"&gt;Workarounds for XDR&lt;/H4&gt;
&lt;P data-start="448" data-end="620"&gt;&lt;STRONG data-start="448" data-end="471"&gt;Resolution Comments:&lt;/STRONG&gt;&lt;BR data-start="471" data-end="474" /&gt;When closing an incident, you can change the status to &lt;EM data-start="529" data-end="539"&gt;Resolved&lt;/EM&gt; and manually add the CSIRT taxonomy flags into the &lt;STRONG data-start="591" data-end="613"&gt;Resolution Comment&lt;/STRONG&gt; field.&lt;/P&gt;
&lt;P data-start="448" data-end="620"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="622" data-end="833"&gt;&lt;STRONG data-start="622" data-end="643"&gt;Resolution Reason:&lt;/STRONG&gt;&lt;BR data-start="643" data-end="646" /&gt;You can select from the predefined resolution reasons (e.g., True Positive, False Positive, Security Testing), but these cannot currently be customized to match ENISA or CSIRT taxonomies.&lt;/P&gt;
&lt;P data-start="622" data-end="833"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="835" data-end="973"&gt;&lt;STRONG data-start="835" data-end="849"&gt;Public API&lt;/STRONG&gt;&lt;BR data-start="849" data-end="852" /&gt;You can use the &lt;CODE data-start="868" data-end="885"&gt;update_incident&lt;/CODE&gt; API to programmatically add comments or update incident details. A sample request body:&lt;/P&gt;
&lt;DIV class="contain-inline-size rounded-2xl corner-superellipse/1.1 relative bg-token-sidebar-surface-primary"&gt;
&lt;DIV class="sticky top-[calc(var(--sticky-padding-top)+9*var(--spacing))]"&gt;
&lt;DIV class="absolute end-0 bottom-0 flex h-9 items-center pe-2"&gt;
&lt;DIV class="bg-token-bg-elevated-secondary text-token-text-secondary flex items-center gap-4 rounded-sm px-2 font-sans text-xs"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="overflow-y-auto p-4" dir="ltr"&gt;&lt;CODE class="whitespace-pre! language-json"&gt;&lt;SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;{&lt;/SPAN&gt;
    &lt;SPAN class="hljs-attr"&gt;"requestdata"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;:&lt;/SPAN&gt; &lt;SPAN class="hljs-punctuation"&gt;{&lt;/SPAN&gt;
        &lt;SPAN class="hljs-attr"&gt;"incidentid"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;:&lt;/SPAN&gt; &lt;SPAN class="hljs-string"&gt;"1001"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;,&lt;/SPAN&gt;
        &lt;SPAN class="hljs-attr"&gt;"updatedata"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;:&lt;/SPAN&gt; &lt;SPAN class="hljs-punctuation"&gt;{&lt;/SPAN&gt;
            &lt;SPAN class="hljs-attr"&gt;"status"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;:&lt;/SPAN&gt; &lt;SPAN class="hljs-string"&gt;"resolvedtruepositive"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;,&lt;/SPAN&gt;
            &lt;SPAN class="hljs-attr"&gt;"resolvecomment"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;:&lt;/SPAN&gt; &lt;SPAN class="hljs-string"&gt;"ENISA Taxonomy: [CSIRT-FLAG-HERE]"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;,&lt;/SPAN&gt;
            &lt;SPAN class="hljs-attr"&gt;"comment"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;:&lt;/SPAN&gt; &lt;SPAN class="hljs-punctuation"&gt;{&lt;/SPAN&gt;
                &lt;SPAN class="hljs-attr"&gt;"comment_action"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;:&lt;/SPAN&gt; &lt;SPAN class="hljs-string"&gt;"add"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;,&lt;/SPAN&gt;
                &lt;SPAN class="hljs-attr"&gt;"value"&lt;/SPAN&gt;&lt;SPAN class="hljs-punctuation"&gt;:&lt;/SPAN&gt; &lt;SPAN class="hljs-string"&gt;"Added CSIRT Taxonomy flags for closure."&lt;/SPAN&gt;
            &lt;SPAN class="hljs-punctuation"&gt;}&lt;/SPAN&gt;
        &lt;SPAN class="hljs-punctuation"&gt;}&lt;/SPAN&gt;
    &lt;SPAN class="hljs-punctuation"&gt;}&lt;/SPAN&gt;
&lt;SPAN class="hljs-punctuation"&gt;}&lt;/SPAN&gt;
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;LI-WRAPPER&gt;&lt;/LI-WRAPPER&gt;&lt;/P&gt;
&lt;P data-start="1343" data-end="1459"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="1343" data-end="1459"&gt;This approach allows structured tagging via comments, but it does not create searchable, normalized taxonomy fields.&lt;/P&gt;
&lt;HR data-start="1461" data-end="1464" /&gt;
&lt;H4 data-start="1466" data-end="1484"&gt;2. Cortex XSIAM:&lt;/H4&gt;
&lt;P data-start="1486" data-end="1651"&gt;If your organization uses Cortex XSIAM, the capability to add these flags is natively supported through &lt;STRONG data-start="1590" data-end="1619"&gt;Editable Incident Layouts&lt;/STRONG&gt; and &lt;STRONG data-start="1624" data-end="1650"&gt;Custom Incident Fields&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H5 data-start="1653" data-end="1681"&gt;Custom Incident Fields:&lt;/H5&gt;
&lt;P data-start="1682" data-end="1722"&gt;You can create dedicated fields such as:&lt;/P&gt;
&lt;UL data-start="1724" data-end="1789"&gt;
&lt;LI data-start="1724" data-end="1742"&gt;
&lt;P data-start="1726" data-end="1742"&gt;CSIRT Taxonomy&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1743" data-end="1770"&gt;
&lt;P data-start="1745" data-end="1770"&gt;Incident Classification&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="1771" data-end="1789"&gt;
&lt;P data-start="1773" data-end="1789"&gt;ENISA Category&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="1791" data-end="1855"&gt;Path:&lt;BR data-start="1796" data-end="1799" /&gt;&lt;STRONG data-start="1799" data-end="1855"&gt;Settings &amp;gt; Configurations &amp;gt; Object Setup &amp;gt; Incidents&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-start="1857" data-end="1933"&gt;These fields can be text, dropdown, multi-select, or other structured types.&lt;/P&gt;
&lt;H5 data-start="1935" data-end="1957"&gt;Editable Layouts:&lt;/H5&gt;
&lt;P data-start="1958" data-end="2001"&gt;You can modify the incident page layout to:&lt;/P&gt;
&lt;UL data-start="2003" data-end="2118"&gt;
&lt;LI data-start="2003" data-end="2039"&gt;
&lt;P data-start="2005" data-end="2039"&gt;Display the custom taxonomy fields&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2040" data-end="2061"&gt;
&lt;P data-start="2042" data-end="2061"&gt;Make them mandatory&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2062" data-end="2118"&gt;
&lt;P data-start="2064" data-end="2118"&gt;Organize them under a dedicated classification section&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="2120" data-end="2269"&gt;This ensures analysts consistently apply the taxonomy during investigation or closure. You can also enforce population of these fields via playbooks.&lt;/P&gt;
&lt;HR data-start="2271" data-end="2274" /&gt;
&lt;H4 data-start="2276" data-end="2297"&gt;Summary Comparison:&lt;/H4&gt;
&lt;DIV class="TyagGW_tableContainer"&gt;
&lt;DIV class="group TyagGW_tableWrapper flex flex-col-reverse w-fit" tabindex="-1"&gt;
&lt;TABLE class="w-fit min-w-(--thread-content-width)" data-start="2299" data-end="2586"&gt;
&lt;THEAD data-start="2299" data-end="2338"&gt;
&lt;TR data-start="2299" data-end="2338"&gt;
&lt;TH class="" data-start="2299" data-end="2309" data-col-size="sm"&gt;Feature&lt;/TH&gt;
&lt;TH class="" data-start="2309" data-end="2322" data-col-size="md"&gt;Cortex XDR&lt;/TH&gt;
&lt;TH class="" data-start="2322" data-end="2338" data-col-size="sm"&gt;Cortex XSIAM&lt;/TH&gt;
&lt;/TR&gt;
&lt;/THEAD&gt;
&lt;TBODY data-start="2380" data-end="2586"&gt;
&lt;TR data-start="2380" data-end="2417"&gt;
&lt;TD data-start="2380" data-end="2405" data-col-size="sm"&gt;Custom Incident Fields&lt;/TD&gt;
&lt;TD data-col-size="md" data-start="2405" data-end="2410"&gt;No&lt;/TD&gt;
&lt;TD data-col-size="sm" data-start="2410" data-end="2417"&gt;Yes&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR data-start="2418" data-end="2448"&gt;
&lt;TD data-start="2418" data-end="2436" data-col-size="sm"&gt;Custom Statuses&lt;/TD&gt;
&lt;TD data-col-size="md" data-start="2436" data-end="2441"&gt;No&lt;/TD&gt;
&lt;TD data-col-size="sm" data-start="2441" data-end="2448"&gt;Yes&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR data-start="2449" data-end="2480"&gt;
&lt;TD data-start="2449" data-end="2468" data-col-size="sm"&gt;Editable Layouts&lt;/TD&gt;
&lt;TD data-col-size="md" data-start="2468" data-end="2473"&gt;No&lt;/TD&gt;
&lt;TD data-col-size="sm" data-start="2473" data-end="2480"&gt;Yes&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR data-start="2481" data-end="2586"&gt;
&lt;TD data-start="2481" data-end="2504" data-col-size="sm"&gt;Recommended Approach&lt;/TD&gt;
&lt;TD data-col-size="md" data-start="2504" data-end="2556"&gt;Use Resolution Comments or external orchestration&lt;/TD&gt;
&lt;TD data-col-size="sm" data-start="2556" data-end="2586"&gt;Use Custom Incident Fields&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-start="2588" data-end="2591" /&gt;
&lt;H4 data-start="2593" data-end="2611"&gt;Recommendation:&lt;/H4&gt;
&lt;UL data-start="2613" data-end="3076" data-is-last-node="" data-is-only-node=""&gt;
&lt;LI data-start="2613" data-end="2809"&gt;
&lt;P data-start="2615" data-end="2809"&gt;If you are using Cortex XDR and require formal structured taxonomy fields, the only current options are comment-based tagging, API-driven enrichment, or external orchestration (e.g., via XSOAR).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2810" data-end="2946"&gt;
&lt;P data-start="2812" data-end="2946"&gt;If you are using Cortex XSIAM, implement Custom Incident Fields and enforce taxonomy usage through layout configuration and playbooks.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="2947" data-end="3076" data-is-last-node=""&gt;
&lt;P data-start="2949" data-end="3076" data-is-last-node=""&gt;If structured taxonomy support is required in Cortex XDR, submit a Feature Request through your Sales Engineer or Account Team.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you feel this has answered your query, please let us know by clicking like and on&amp;nbsp;&lt;STRONG&gt;"mark this as a Solution".&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks &amp;amp; Regards,&lt;BR /&gt;S. Subashkar Sekar&lt;/P&gt;</description>
      <pubDate>Tue, 17 Feb 2026 19:39:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-add-more-values-to-incident-classification/m-p/1248400#M9137</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-17T19:39:07Z</dc:date>
    </item>
    <item>
      <title>Re: XDR add more values to incident classification</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-add-more-values-to-incident-classification/m-p/1248480#M9143</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I have &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp; integrated with &lt;LI-PRODUCT title="Cortex XSOAR" id="Cortex_XSOAR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;(whether on-prem or cloud) for incident resolution through XSOAR, then I can perform the classification there. However, I only retrieve the data via XSOA&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Do you know if this also works with XSOAR Cloud? I know it works in the on-prem version because I already have playbooks configured for that. &lt;BR /&gt;&lt;BR /&gt;I assume the cloud version behaves the same way.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 13:26:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-add-more-values-to-incident-classification/m-p/1248480#M9143</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-02-18T13:26:01Z</dc:date>
    </item>
    <item>
      <title>Re: XDR add more values to incident classification</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-add-more-values-to-incident-classification/m-p/1248509#M9146</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/241098"&gt;@susekar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="0" data-end="104"&gt;Another question, if you happen to know: is it possible to export all incidents to an external platform?&lt;/P&gt;
&lt;P data-start="106" data-end="243"&gt;For example, can I export incident data to a SQL database, including fields such as &lt;STRONG data-start="190" data-end="204"&gt;IncidentID&lt;/STRONG&gt;, &lt;STRONG data-start="206" data-end="221"&gt;Description&lt;/STRONG&gt;, and &lt;STRONG data-start="227" data-end="242"&gt;CloseReason&lt;/STRONG&gt;?&lt;/P&gt;
&lt;P data-start="245" data-end="450" data-is-last-node="" data-is-only-node=""&gt;I need to perform a more granular classification of incidents — not just a true/false categorization — but also include additional flags aligned with &lt;SPAN class="hover:entity-accent entity-underline inline cursor-pointer align-baseline"&gt;&lt;SPAN class="whitespace-normal"&gt;European Union Agency for Cybersecurity&lt;/SPAN&gt;&lt;/SPAN&gt; (ENISA) taxonomy.&lt;BR /&gt;&lt;BR /&gt;I'll use only &lt;LI-PRODUCT title="Cortex XDR" id="Cortex_XDR"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 18:10:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-add-more-values-to-incident-classification/m-p/1248509#M9146</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2026-02-18T18:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: XDR add more values to incident classification</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-add-more-values-to-incident-classification/m-p/1248510#M9147</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the response.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, it is possible to export incident data from Cortex XDR to an external platform like a SQL database, though the method depends on whether you require a manual one-time export or a programmatic, automated integration.&lt;/P&gt;
&lt;H5&gt;1. Export Methods for Incidents:&lt;/H5&gt;
&lt;P&gt;To move data to an external SQL database, you have two primary options:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Public API (Recommended for Automation):&lt;/STRONG&gt;&lt;BR /&gt;You can use the Cortex XDR Public API to programmatically retrieve incident data. The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;get_incidents&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;get_incident_extra_data&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;endpoints provide structured JSON responses that include the fields you requested.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;IncidentID:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Available as&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;incident_id&lt;/CODE&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Description:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Available as&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;description&lt;/CODE&gt;.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;CloseReason:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Available via fields such as&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;resolution_status&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;resolution_comment&lt;/CODE&gt;.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;To implement this, you would write a script (e.g., in Python) to call the API and then insert that data into your SQL database. You will need to generate an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;API Key&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;API Key ID&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in the Cortex XDR console under&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Settings → Configurations → API Keys&lt;/CODE&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Manual Export (UI):&lt;/STRONG&gt;&lt;BR /&gt;For manual analysis, you can export incidents directly from the console as a Tab-Separated Values (TSV) file, which can then be imported into a SQL database.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Navigate to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;Incident Response → Incidents&lt;/CODE&gt;.&lt;/LI&gt;
&lt;LI&gt;Switch to&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Table View&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Detail View&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(Mailbox View).&lt;/LI&gt;
&lt;LI&gt;Apply desired filters and timeframes (within the 180-day retention limit).&lt;/LI&gt;
&lt;LI&gt;Click the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Export to file&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;icon.&lt;/LI&gt;
&lt;/OL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2026 19:19:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-add-more-values-to-incident-classification/m-p/1248510#M9147</guid>
      <dc:creator>susekar</dc:creator>
      <dc:date>2026-02-18T19:19:17Z</dc:date>
    </item>
  </channel>
</rss>

